In effectSB 149 (2024); amended by SB 226, HB 452, SB 332 (2025) and HB 320 (2026)

Utah Artificial Intelligence Policy Act: Compliance Checklist

A practical checklist of the main obligations to satisfy under this law.

Compliance checklist

Run through these items to scope your obligations under Utah Artificial Intelligence Policy Act. Not legal advice; verify with counsel before acting.

  1. Confirm scope: does the law apply to your operations? See Who Must Comply or use the Compliance Checker.
  2. Inventory in-scope AI systems and classify them by role (developer/deployer) and decision type.
  3. Address each obligation:
    • disclosureA supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human when the individual makes a clear and unambiguous request about whether AI is being used; regulated-occupation providers must prominently disclose GenAI use for high-risk AI interactions, verbally at the start of verbal interactions or in writing before written interactions.Utah Code § 13-77-103
    • governanceMaintain accountability for consumer-protection compliance when generative AI makes a violative statement, undertakes a violative act, or is used in furtherance of a violation; Chapter 77 states that generative AI is not a defense to statutes administered and enforced by the Division of Consumer Protection.Utah Code § 13-77-102
    • data handlingMental health chatbot suppliers may not sell or share individually identifiable health information or a Utah user's chatbot input with a third party, and must keep Chapter 72a privacy controls separate from the general Chapter 77 consumer-transaction disclosure rule.Utah Code § 13-72a-201
    • disclosureMental health chatbot suppliers must clearly and conspicuously disclose that the chatbot is artificial intelligence technology and not human before features are accessed, at the beginning of an interaction after a seven-day gap, and whenever a Utah user asks or prompts about whether AI is being used.Utah Code § 13-72a-203
  4. Adopt a federal control framework: NIST AI RMF or ISO/IEC 42001 to demonstrate due care.
  5. Document evidence of compliance for each obligation, refreshed at the cadence the law requires.
  6. Build the AG-notification path if the law requires it (Colorado, California SB 53).
  7. Set the refresh cadence — annual for most impact-assessment regimes; continuous for monitoring.
More on this law

We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.